Asp.net ºǫ́µ÷ÓÃjs·½·¨(ת)
1. ÓÃResponse.Write·½·¨
¡¡¡¡´úÂëÈçÏ£º
Response.Write("<script type='text/javascript'>alert("XXX");</script>");
´Ë·½·¨È±ÏݾÍÊDz»Äܵ÷Óýű¾ÎļþÖеÄ×Ô¶¨ÒåµÄº¯Êý£¬Ö»Äܵ÷ÓÃÄÚ²¿º¯Êý£¬¾ßÌåµ÷ÓÃ×Ô¶¨ÒåµÄº¯ÊýÖ»ÄÜÔÚResponse.WriteдÉϺ¯Êý¶¨ Ò壬±ÈÈç
Response.Write("<script type='text/javascript'>function myfun(){}</script>");
2.ÓÃClientScriptÀà
¡¡¡¡´úÂëÈçÏ£ºÔÚÏëµ÷ÓÃij¸öjavascript½Å±¾º¯ÊýµÄµØ·½Ìí¼Ó´úÂ룬עÒâÒª±£Ö¤MyFunÒѾÔڽű¾ÎļþÖж¨Òå¹ýÁË¡£
ClientScript.RegisterStartupScript(ClientScript.GetType(), "myscript", "<script>MyFun();</script>");
¡¡¡¡Õâ¸ö·½·¨±ÈResponse.Write¸ü·½±ãһЩ£¬¿ÉÒÔÖ±½Óµ÷Óýű¾ÎļþÖеÄ×Ô¶¨Ò庯Êý¡£
3.ÆÕͨµÄÌí¼Ó¿Ø¼þµÄAttributesÊôÐÔ
¡¡¡¡¶ÔÓÚÆÕͨ°´Å¥¾ÍÊÇ£ºButton1.Attributes.Add("onclick","MyFun();");
¡¡¡¡Ö»ÄÜÔÚOnloadÖлòÀàËÆÓÚonloadµÄ³õʼ»¯¹ý³ÌÖÐÌí¼Ó²ÅÓÐЧ¡£¶øÇÒÊÇÏÈÖ´Ðнű¾º¯Êý£¬ÎÞ·¨¸Ä±äÖ´ÐÐ˳Ðò¡£
×¢Ò⣬ÒÔÉÏËùÓз½·¨ÖУ¬ºǫ́´úÂ붼²»ÄÜÓÐת»¯µ±Ç°Ò³µÄ´úÂ룬±ÈÈçRedirectµÈ£¬Òª°Ñתҳ´úÂë·ÅÔڽű¾ÀïÃæ
Ïà¹ØÎĵµ£º
1. BinÎļþ¼Ð
BinÎļþ¼Ð°üº¬Ó¦ÓóÌÐòËùÐèµÄ£¬ÓÃÓڿؼþ¡¢×é¼þ»òÕßÐèÒªÒýÓõÄÈκÎÆäËû´úÂëµÄ¿É²¿Êð³ÌÐò¼¯¡£¸ÃĿ¼ÖдæÔÚµÄÈκÎ.dllÎÄ ¼þ½«×Ô¶¯µØÁ´½Óµ½Ó¦ÓóÌÐò¡£
2. App_BrowserÎļþ¼Ð
¸Ã¿ÉÑ¡µÄÎļþ¼Ð°üº¬.browserÎļþ¡£.browserÎļþÃèÊöä¯ÀÀÆ÷(²»¹ÜÊÇÒƶ¯É豸ä¯ÀÀÆ÷£¬»¹ÊÇ̨ʽ»úä¯ÀÀÆ÷)µÄÌØ Õ÷ºÍ¹¦ÄÜ¡£
3. ......
ÔÚ¡¶ASP.NET¿ª·¢£ºÔÚÓû§¿Ø¼þÖÐÌí¼ÓÊôÐÔ¡·ÕâһƪÎÄÕÂÖÐÎÒÃǶ¨ÒåÁËÒ»¸öÓû§µÇ¼µÄÓû§¿Ø¼þUserLogin.ascx Îļþ£¬ÀïÃæ°üº¬ÁËÒ»¸öLinkButton·þÎñÆ÷°´Å¥¿Ø¼þ£¬µ±Óû§µ¥»÷¸Ã°´Å¥Ê±·þÎñÆ÷¶Ë»á×Ô¶¯Éú³ÉÒ»¸ö»Ø·¢À´¼¤·¢Page.Loadʼþ¡£³ýÁË·þÎñÆ÷×Ô¶¯²úÉú»Ø·¢À´¼¤·¢Page.LoadʼþÍ⣬ÎÒÃÇ¿ÉÒÔ¸øLinkButtonÌí¼ÓÒ»¸öËü×Ô¼ºµÄʼþ ......
ʹÓà SqlDataSource ¿Ø¼þÖ»ÐèºÜÉٵĴúÂë»òÎÞÐèÈκδúÂë¼´¿É´ÓÊý¾Ý¿âÖмìË÷Êý¾Ý¡£SqlDataSource ¿Ø¼þ¿ÉÓÃÓÚÈκξßÓйØÁª ADO.NET Ìṩ³ÌÐò£¨ÔÚÅäÖÃÎļþµÄ DbProviderFactories ½ÚÖÐÅäÖ㩵ÄÊý¾Ý¿â£¬°üÀ¨ Microsoft SQL Server¡¢Oracle¡¢ODBC »ò OLE DB Êý¾Ý¿â£¨Èç Microsoft Access£©¡£ÄúÔÚÅäÖÃʱָ¶¨ SqlDataSource ʹÓõ ......
¿ÉÒÔʹÓà SqlDataSource ¿Ø¼þÐÞ¸ÄÊý¾Ý¿âÖеÄÊý¾Ý¡£Ê¹Óøüз½°¸ÖÐµÄ SqlDataSource ¿Ø¼þµÄ×î³£Ó÷½·¨ÊǼìË÷Êý¾Ý²¢Ê¹ÓÃÊý¾Ý°ó¶¨ Web ·þÎñÆ÷¿Ø¼þ£¨Èç GridView¡¢DetailsView »ò FormView ¿Ø¼þ£©ÏÔʾÊý¾Ý¡£¿ÉÒÔÅäÖÃÊý¾Ý°ó¶¨¿Ø¼þºÍ SqlDataSource ÒÔ¸üÐÂÊý¾Ý¡£´ó¶àÊýÊý¾Ý°ó¶¨¿Ø¼þ¶¼ÔÊÐíÄú½«Æä ......
ͨ¹ýAsp.net(C#)Ó¦ÓóÌÐò¶ÁÈ¡±¾µØÉÏ´«µÄExcleÎļþ,´æ·Åµ½DataSetÖÐ,ͨ¹ýDataSetÖеķ½·¨Ö±½ÓÉú³ÉXMLÎļþ.
C# Code
if (this.FileUpload1.PostedFile != null)
{
string filename = this.FileUpl ......